{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:6HFXZBATUZ667YBL57C4ELHL4I","short_pith_number":"pith:6HFXZBAT","schema_version":"1.0","canonical_sha256":"f1cb7c8413a67defe02befc5c22cebe234e312145c89f10950a0b7605e0f4533","source":{"kind":"arxiv","id":"2507.03646","version":1},"attestation_state":"computed","paper":{"title":"When There Is No Decoder: Removing Watermarks from Stable Diffusion Models in a No-box Setting","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Jianbing Ni, Tianyi Tang, Xiangman Li, Xiaodong Wu, Yong Yu","submitted_at":"2025-07-04T15:22:20Z","abstract_excerpt":"Watermarking has emerged as a promising solution to counter harmful or deceptive AI-generated content by embedding hidden identifiers that trace content origins. However, the robustness of current watermarking techniques is still largely unexplored, raising critical questions about their effectiveness against adversarial attacks. To address this gap, we examine the robustness of model-specific watermarking, where watermark embedding is integrated with text-to-image generation in models like latent diffusion models. We introduce three attack strategies: edge prediction-based, box blurring, and "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2507.03646","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-07-04T15:22:20Z","cross_cats_sorted":[],"title_canon_sha256":"cce153fa27936775137fbde914effa0e5bf3ad2b6d024952ba92299286bc6044","abstract_canon_sha256":"e6d15e8e9dcd74aaf2c075df9fedbfdcb17e08469afe32da4f8ad6493a35d4ac"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:32:03.114628Z","signature_b64":"yXtKz07VrdtUkNhAGYoPV+yc8FNeCBJIFWCzwIUEyuKjF/YcBW7aPzPVEp19dAuwqgY+RgKUt/cv1X3lM0DlCA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"f1cb7c8413a67defe02befc5c22cebe234e312145c89f10950a0b7605e0f4533","last_reissued_at":"2026-07-05T11:32:03.114160Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:32:03.114160Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"When There Is No Decoder: Removing Watermarks from Stable Diffusion Models in a No-box Setting","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Jianbing Ni, Tianyi Tang, Xiangman Li, Xiaodong Wu, Yong Yu","submitted_at":"2025-07-04T15:22:20Z","abstract_excerpt":"Watermarking has emerged as a promising solution to counter harmful or deceptive AI-generated content by embedding hidden identifiers that trace content origins. However, the robustness of current watermarking techniques is still largely unexplored, raising critical questions about their effectiveness against adversarial attacks. To address this gap, we examine the robustness of model-specific watermarking, where watermark embedding is integrated with text-to-image generation in models like latent diffusion models. We introduce three attack strategies: edge prediction-based, box blurring, and "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2507.03646","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2507.03646/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2507.03646","created_at":"2026-07-05T11:32:03.114218+00:00"},{"alias_kind":"arxiv_version","alias_value":"2507.03646v1","created_at":"2026-07-05T11:32:03.114218+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2507.03646","created_at":"2026-07-05T11:32:03.114218+00:00"},{"alias_kind":"pith_short_12","alias_value":"6HFXZBATUZ66","created_at":"2026-07-05T11:32:03.114218+00:00"},{"alias_kind":"pith_short_16","alias_value":"6HFXZBATUZ667YBL","created_at":"2026-07-05T11:32:03.114218+00:00"},{"alias_kind":"pith_short_8","alias_value":"6HFXZBAT","created_at":"2026-07-05T11:32:03.114218+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/6HFXZBATUZ667YBL57C4ELHL4I","json":"https://pith.science/pith/6HFXZBATUZ667YBL57C4ELHL4I.json","graph_json":"https://pith.science/api/pith-number/6HFXZBATUZ667YBL57C4ELHL4I/graph.json","events_json":"https://pith.science/api/pith-number/6HFXZBATUZ667YBL57C4ELHL4I/events.json","paper":"https://pith.science/paper/6HFXZBAT"},"agent_actions":{"view_html":"https://pith.science/pith/6HFXZBATUZ667YBL57C4ELHL4I","download_json":"https://pith.science/pith/6HFXZBATUZ667YBL57C4ELHL4I.json","view_paper":"https://pith.science/paper/6HFXZBAT","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2507.03646&json=true","fetch_graph":"https://pith.science/api/pith-number/6HFXZBATUZ667YBL57C4ELHL4I/graph.json","fetch_events":"https://pith.science/api/pith-number/6HFXZBATUZ667YBL57C4ELHL4I/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/6HFXZBATUZ667YBL57C4ELHL4I/action/timestamp_anchor","attest_storage":"https://pith.science/pith/6HFXZBATUZ667YBL57C4ELHL4I/action/storage_attestation","attest_author":"https://pith.science/pith/6HFXZBATUZ667YBL57C4ELHL4I/action/author_attestation","sign_citation":"https://pith.science/pith/6HFXZBATUZ667YBL57C4ELHL4I/action/citation_signature","submit_replication":"https://pith.science/pith/6HFXZBATUZ667YBL57C4ELHL4I/action/replication_record"}},"created_at":"2026-07-05T11:32:03.114218+00:00","updated_at":"2026-07-05T11:32:03.114218+00:00"}